heroui logo

GitHub Organizations Disable Classic Branch Protection Rule

Splunk Security Content

View Source
Summary
This analytic detects the disabling of classic branch protection rules in GitHub Organizations through monitoring their audit logs for removal events. Classic branch protection is crucial as it enforces safeguarding code quality, preventing central elements like direct pushes and ensuring adherence to code reviews. Disabled protections might indicate malicious attempts to bypass security controls, leading to unauthorized changes, code tampering, or even introducing vulnerabilities in the software supply chain. Hence, tracking branches without these protections is vital for detecting potential malicious activity and maintaining software integrity.
Categories
  • Cloud
  • Infrastructure
  • Application
Data Sources
  • Logon Session
  • Application Log
  • User Account
  • Cloud Service
ATT&CK Techniques
  • T1562.001
  • T1195
Created: 2025-01-17